Could logs be lost when network equipment is powered down?¶
Yes. Powering down or restarting network equipment can erase volatile logs and live state, so the evidential cost should be assessed before changing its power state.
What may exist only while the device is running¶
Routers, switches, firewalls and wireless access points often retain connection tables, address leases, VPN sessions, counters, uptime and buffered events in memory. A restart may clear those records, assign new addresses and cause devices to reconnect. The post-restart view can therefore differ substantially from the earlier network state.
Some equipment forwards events to a log server or cloud console, but forwarding may be delayed, filtered or incomplete. Shutdown can prevent the final buffered entries from reaching that destination. A central copy should be assessed for its own scope, timing and retention rather than assumed to be complete.
Preserve the live state before a justified change¶
Where delay does not create unacceptable risk, record the equipment, displayed time and time zone, uptime, active sessions, connected ports, address tables, alerts and visible logs. Identify local, provider-hosted and forwarded records and capture any warning about data loss.
If shutdown or restart is necessary, document the reason, authority, exact time and affected equipment. After restoration, record the new uptime, changed addresses, reconnecting devices and missing entries. This separates observations made before the event from records generated by recovery.
Key takeaway
Treat a power change as a potential loss of volatile network evidence, and distinguish the preserved pre-change state from incomplete or newly generated post-restart records.